SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft Defender for Cloud to secure its hybrid cloud workload. The security team needs to ensure that all virtual machines (VMs) have Just-In-Time (JIT) VM access enabled. What should they use to enforce this across subscriptions?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign an Azure Policy initiative that requires JIT VM access
Azure Policy can enforce JIT VM access via a built-in initiative. Assigning an Azure Policy initiative across subscriptions ensures that any VM without JIT VM access enabled is non-compliant and can be remediated. Option B (Azure Blueprints) is an orchestration tool that can deploy resources but does not enforce configuration across subscriptions at scale. Option C (Defender for Cloud servers plan) enables security features but does not enforce specific settings like JIT. Option D (Secure Score recommendations) is advisory and does not enforce compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign an Azure Policy initiative that requires JIT VM access
Why this is correct
Assigning an Azure Policy initiative is the most effective method for enforcing Just-in-Time (JIT) VM access across an Azure environment. An initiative groups multiple policy definitions, allowing for comprehensive governance and consistent application of security controls. When assigned, it can audit for non-compliant resources and automatically remediate them to ensure all virtual machines adhere to the JIT access requirement, thereby significantly reducing the attack surface.
- ✗
Use Azure Blueprints to deploy JIT access configuration
Why it's wrong here
Azure Blueprints were a service designed for deploying repeatable sets of Azure resources and configurations, but they have been deprecated by Microsoft. The recommended approach for achieving similar outcomes, especially for ongoing governance and compliance enforcement like JIT access, is now a combination of Azure Deployment Stacks for resource deployment and Azure Policy. Therefore, attempting to use Blueprints for JIT access configuration is an outdated and unsupported approach.
- ✗
Enable the Defender for Cloud servers plan
Why it's wrong here
Enabling the Microsoft Defender for Cloud servers plan provides advanced threat protection, vulnerability assessments, and security alerts for virtual machines. While it integrates with JIT VM access by providing recommendations and monitoring capabilities, the plan itself does not enforce the JIT access configuration. Its primary role is detection, protection, and response against threats, not policy-driven access control enforcement.
- ✗
Implement a Secure Score recommendation for JIT access
Why it's wrong here
Implementing a Secure Score recommendation for JIT access involves reviewing and acting upon security suggestions provided by Microsoft Defender for Cloud. Secure Score is a measurement of an organization's security posture and offers actionable advice to improve it by highlighting areas needing attention. However, it is a reporting and guidance tool, not an enforcement mechanism; it recommends changes but does not automatically apply or mandate JIT access.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Initiative
An initiative is a formal, structured effort or project undertaken by an organization to achieve a specific strategic goal, often involving changes to IT systems, policies, or processes.
Key term
Secure Score
Secure Score is a measurement tool in Microsoft 365 that shows how secure your organization is based on the security features you have enabled and configured.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.